Reply to "Comment on quantum secret sharing based 
on reusable Greenbergr-Horne-Zeilinger states as secure 

carriers" 



^ ■ V. Karimipour ^ 

o 

Department of Physics, Sharif University of Technology, 
^ ■ P.O. Box 11365-9161, 

Tehran, Iran 



> 

a^ 
o 
in 
o 

• Abstract 

o 

In a recent comment, it has been shown that in a quantum secret sharing protocol 
p • proposed in [S. Bagherinezhad, V. Karimipour, Phys. Rev. A, 67, 044302, (2003)], one of 

the receivers can cheat by splitting the entanglement of the carrier and intercepting the 
C I secret, without being detected. In this reply we show that a simple modification of the 

^ ' protocol prevents the receivers from this kind of cheating. 
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To set up the context and the notations, it is appropriate to first review briefly the protocol 
itself |lj and the basic feature of the attack or cheating suggested in j2|. 



1 The basic steps of the protocol and the cheating 

First we need the concept of a reusable secure carrier , . A Bell state like 

|</'+)a6 = ^(|00) + |ll)U 

shared between Alice(a) and Bob(b) can be used as a reusable secure carrier between two parties 
as follows. Alice entangles a qubit |g)i by the action of a CNOT gate Cai (acting on the qubit 
1 and controlled by a), which produces a state like 

-^(|00g) + |llg)Ui. 

At the destination Bob disentangles the qubit by a CNOT operation Chi-, leaving the carrier in 
its original state for reusing. During the transmission the qubit has been disguised in a highly 
mixed state. 
Any of the Bell states 

\<t^^)al> = ^(|00) ± 111)).,, = ^(|01) ± |10)),, (1) 

can be used as a carrier. 

For three parties 1^, a carrier shared between Alice(a), Bob(b) and Charlie(c) can be a GHZ 
state like 

\G H Z) := ^{\000) + \in)) abc, (2) 

or an even parity state like 

1^) := ^(|000) + |110) + |101) + |011)W (3) 

Throughout P, the comment [2] and the present reply the subscripts a, b and c are used for 
the quibts shared by, or the local operators acted by, Alice, Bob and Charlie respectively, while 
the subscripts 1 and 2 are used for the qubits sent to Bob and Charlie respectively. 



It was shown in ^ that by suitable local operations, Alice can send a qubit q to Bob and 
Charlie, by entangling it to the above carriers (hence hiding it from Eavesdroppers). In order 
to share the secret between Bob and Charlie, half of the bits (the bits in the odd rounds) were 
sent to Bob and Charlie, as states of the form \qq)i2 which they could read without the help 
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of each other and the other half (the bits in the even rounds) were sent to them in the form 
■:^{\q 0) + 1^ 1)12) which they could use to decipher the value of q only by their cooperation. 
Note that q = 1 + q mod 2. 

In order to be able to send both types of states in disguised form, Alice needs to use two 
types of carriers, namely the \GHZ) carrier for the states \q q) and the \E) carrier for the states 
0) + 1^ !))■ The interesting point is that the two types of carriers are transformed to each 
other at the end of every round by the local action of Hadamard gates by the three parties, 
due to the following easily verified property 

H ® H ® H\GHZ) = \E), H ®H ®H\E) = \GHZ). (4) 

An important property which requires careful attention is that the carrier alternates be- 
tween the above two forms regardless of the value of the qubit q which has been sent to Bob 
and Charlie by Alice. 

In the authors show that in the second round where a qubit say has been encoded 
as :^|00) + 1 11) 12 and entangled to the carrier \E), Bob (assuming that he has access to the 
channel between Alice and Charlie) can intercept the qubit 2 sent to Charlie (assuming that 
he has access to the channel used between Alice and Charlie) and perform a suitable unitary 
operation [4i2, on the state of the carrier and the two bits 1 and 2, to split the carrier \E) to 
two simple carriers of the type^ This process is shown schematically in figure (P). 

Let us denote by 52 the qubit sent by Alice in the second round. Bob keeps this qubit for 
himself and denotes it hereafter by 6, since it is now in possession of Bob and plays a role as 
part of his new carriers. 

It is important to note that the pattern of entanglement splitting depends on the value of 
this qubit g2 as follows (equation 3 of the comment): 

1^) \^^)al®\^^W if 92 = 0, (5) 

1^) — ^ \i^^)al®\r)bc if 92 = 1. (6) 

As it stands in [2], this does not harm the cheating strategy of Bob, since as mentioned 
before any of the Bell states can be used as a carrier between two parties. 

He then uses the above two pairs of entangled states for retrieving the qubits sent by Alice 
on his own and sending counterfeit qubits to Charlie in a clever way so that to avoid detection 
after public announcement of subsequence of the bits. 

What is crucial in this attack is that Bob acts by Hadamard gates on his qubits h and h 
along with Alice and Charlie who are doing the same thing at the end of each round. In this 
way he almost maintains the pattern of the new carriers, which he has created in the second 
round, between himself and the other two parties. 
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Figure 1: (Color Online) According to the comment Bob can split the three party carrier into 
two carriers between him and the other parties. The dashed arrows show the bits sent by Alice, 
the solid lines indicate the entangled states (carrier (s)) shared between the parties. 

The reason for "almost" is that the Hadamard operations act as follows (equation 4 of the 
comment): 



H""' ■.\<P~)ai®\<p-)bc^\^^)ai®\i^'-W (8) 

Thus if the qubit q2 was zero, the new two-party carriers remain fixed at \4>~^)ab ® \4'~^)bc, 
otherwise they alternate between the two forms \(p~)ab^\'P~)bc and \i'~^)ab^\'^~^)bc- As mentioned 
above this does not affect his cheating strategy, as all the Bell states are good secure carriers. 



2 Prevention of cheating 

At first sight one may argue that Alice and Charlie who are no longer entangled after Bob's 
trick, can detect their new disentangled situation (i.e. by testing a Bell inequality) and hence 
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detect Bob's cheating. However this test requires statistical analysis which requires many mea- 
surements. In each measurement the carrier collapses and will not be usable anymore. Being in 
conflict with the whole idea of reusable carrier, we do not follow this line of argument. Instead 
we modify the protocol in a way which prevents Bob's from entanglement splitting. 

To this end we note that the operator H®^ is not the only operator which transforms the 
carriers \GHZ) and \E) into each other. Consider a unitary operator of the form 

where 9 is an arbitrary parameter 6* G [0, 27r). For ^ = this is the usual Hadamard operator. 
Note that 

H{em = e-'^m + H{em = ^'^'ti - (10) 

A simple calculation shows that a generalization of (j3)) is possible in the following form 

H{9a) ® H{e,) (g) H{e,)\GHZ) = \E) H{9a)-' ® H{9t)-' ® H{9,)-^\E) = \GHZ), (11) 

provided that 9a + 9i, + 9^ = mod 2tt. Therefore in the modifled protocol Alice, Bob and 
Charlie act alternatively by the operators Hg^, Hq^, and Hq^, and their inverses, on the qubits 
in their possession. The angles 9a, 9^ and 9c can be announced publicly at the beginning of the 
protocol. We now show that after entanglement splitting. Bob can not retain his pattern of 
carriers by any operator [/^ ^ which he acts on his qubits b and b. We need the following 

Proposition: 

a: The only operator [/^^ which in conjunction with {H{9a) (8> H{9c))ac leaves invariant the 
state 10+)^^ ® is the operator U-^ ^^ = {H{-9a) ® H{-9})\^. 

b: The only operator Ul^^ which in conjunction with {H{9a) ®H{9c))ac transforms the state 
I^~)a6 ® \4>~)bc into \i)~)ab ® \'>P~)bc IS the operator l^ ^, = {H{9aY ® H{9cf)i^^, where T means 
transpose. 

Proof: The proof is simply straightforward calculations. We highlight the basic steps. 
Consider part a. We want an operator Ui ^ such that 

{Ha 0Ui,0 HcM^)^i ® \<P^)bc = \<P^)ah ® \<P^)bc, (12) 

where we use Ha as an abbreviations of H{9a)a and so forth. Acting on both sides by Ha^ ® 
I ® I ® H~^ we obtain 
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We now rearrange both sides to the convenient form 



{la ^Ic®Ul J (|00) ® |00) + |10) ® |10) + |01) ® |01) + 111) ® \n))acbb . 

= (H-' ® H;' ® ® h) (|00) ® |00) + |10) ® |10) + |01) ® |01) + 111) ® |11)),,^^, , (14) 

and effect the operators and on the right hand side by using (|Tnjl . After comparing 
both sides in the basis {|00), |01), |10), 1 11) }ac we arrived at the stated assertion, namely that 

Similar reasoning proves part b. 

We now come to our main conclusion. Bob, being among the original legitimate parties 
knows the values of the angles, However in order to scape detection he has to apply 

either the operator ^ = (H^-Oa) O i^(-6'J)^j, or V^^, = {H{9a)'^ ® H{e^Y)i^^ at the end of 
each round. However his choice depends on the value of the second bit which he does not know. 
Without this knowledge he can not retain the pattern of fraud carriers which he has constructed 
between him and the other two parties. This then introduces errors in half of the bits sent by 
Alice and received by him and Charlie, which in subsequent public announcement of substrings 
of bits reveals his cheating. Incidentally we note that the equality H{—9) = H{0)^ holds only 
for 6' = 0, that is for the ordinary Hadamard gate. 
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